mpanichello
1 Nickel

Optiplex 7040 Enable AMT

When booting the machine, pressing F12 does not provide an option to configure AMT. The option to display <CTRL-P> is enabled in the BIOS but that option does not appear during boot, and pressing the key combo does nothing. In Windows, device manager does show the management engine. Is there a firmware update that is needed to be able to configure vPro options? My understanding is that this can be configured from Dell - if the machines we have were ordered with vPro disabled in firmware, how do we re-enable it, as the hardware obviously supports it - i7-6700 and a Q-series chipset with Intel NIC.

Thanks!

-Mike

0 Kudos
14 Replies
9 Rhodium

RE: Optiplex 7040 Enable AMT

There's no easy way to enable vPro if the board has it disabled -- it requires extensive BIOS hacking to accomplish.  

0 Kudos
7 Plutonium

RE: Optiplex 7040 Enable AMT

Systems without INTEL AMT or if the control P MEBx  has been disabled is a one way trip.  This is not reversible.

It is not possible to change the Manageability Mode when options 3 or 4 have been selected. 

4 No TLS * 310-9496 RU572 Short: TLS Encryption Disabled,OPTI 
Long: TLS Encryption Disabled, Dell OptiPlex 
Option Online: TLS Encryption Disabled 
MOD MOD,INFO,MGMT,TLS,DISABLE,OPTI

* The No TLS option only applies to the following countries: China, France, Hong Kong, Israel, Korea, Poland, and Russia.

 

This is true from the 755 and up.

Article ID : 52060 Date Published : 2007-09-05 Journal ID : d2fe9d65-b1a0-4fd7-b75c-52e4b9862f38

Manageability Mode Options on Replacement System Boards for the OptiPlex™ 755

The OptiPlex™ 755 has one system board per chassis available for dispatch. The system board is shipped in manufacturing mode and the end user or service provider must select the manageability option upon first boot. There are four manageability options that might be seen on the customer order according to the original configuration purchased.

For information on what manageability options were configured when the system was originally shipped, refer to Table 1

Label SKUPart NumberDescription
Basic Systems Management Mode
1 vPro
AMT
DASH Ready
310-9491 CU245 Short: Advanced Client Systems Management,w/vPro,OPTI 
Long: Advanced Client Systems Management,with vPro,Dell OptiPlex 
Option Online: Advanced Client Systems Management (w/ vPro) 
MOD MOD,LBL,MGMT,VPRO/AMT/DASH
1 AMT
DASH Ready
310-9494 HP413 Short: Advanced Client Systems Management,w/iAMT,OPTI 
Long: Advanced Client Systems Management,with iAMT,Dell OptiPlex 
Option Online: Advanced Client Systems Management (w/ iAMT) 
MOD MOD,INFO,MGMT,AMT/DASH,OPTI
2 ASF Only 310-9492 CU377 Short: Basic Client Systems Management,w/ASF,OPTI 
Long: Basic Client Systems Management,with ASF,Dell OptiPlex 
Option Online: Basic Client Systems Management (w/ ASF) 
MOD MOD,INFO,MGMT,ASF ENABLED
3 ME Disabled 310-9493 XT411
NN180
Short: Client Systems Management Disabled,OPTI 
Long: Client Systems Management Disabled, Dell OptiPlex 
Option Online: Client Systems Management Disabled 
MOD MOD,INFO,MGMT,MEBX,DISABLE,OPT 
MOD MOD,INFO,1-WATT,BIOS,OPTI,755
Deployment Mode
N/A Disables Remote Configuration 310-9495 CU378 Short: One Touch Provisioning Support,OPTI 
Long: One Touch Provisioning Support, Dell OptiPlex 
Option Online: One Touch Provisioning Support 
MOD MOD,INFO,MGMT,ONE TOUCH CNFG
2 ASF with AMT option 310-9497 WK835 Short: LEGACY ASF SETTING FOR IAMT,OPTI 
Long: Legacy ASF Setting for iAMT,Dell OptiPlex 
Option Online: Legacy ASF Setting for iAMT 
MOD MOD,INFO,MGMT,ASF ROLL BACK
4 No TLS * 310-9496 RU572 Short: TLS Encryption Disabled,OPTI 
Long: TLS Encryption Disabled, Dell OptiPlex 
Option Online: TLS Encryption Disabled 
MOD MOD,INFO,MGMT,TLS,DISABLE,OPTI

* The No TLS option only applies to the following countries: China, France, Hong Kong, Israel, Korea, Poland, and Russia.

Table 1: Manageability Mode Labels

When issuing a dispatch, leave a note in the Comments to Service Provider field with the Manageability Mode option that must be selected after the system board is replaced.


The Manageability Mode Sticker on the Chassis Cover for the OptiPlex™ 755

On the inside of the removable side cover there is a 2" x 1" label denoting the manageability mode with which the system was purchased (Figures 1 and 2).


Figure 1: The Manageability Mode Sticker Location on the OptiPlex 755


Figure 2: The Four Different Manageability Mode Stickers on the OptiPlex 755


Configure the Manageability Mode on a Replacement System Board

 Note:  
  When the number for the manageability mode is entered and confirmed, it is unable to be changed. If the incorrect manageability mode is selected, it is possible the system board must be replaced depending on the option selected.  
  1. Turn the system off and remove the power cord.

  2. Open the chassis cover and locate the manageability mode sticker.

  3. Verify the number on the manageability mode sticker.

  4. Close the chassis cover, plug the power cord back into the system, and turn the system on.

  5. At the Type the number corresponding with your selection: prompt, press the key for the number obtained from the sticker (Figure 1).


    Figure 1: Prompt Received After Replacing the System Board

  6. At the Continue with selection? (Y/N) prompt, press <Y>.

  7. After the system shuts down, turn the system back on to continue with normal operation.


Change Manageability Modes 1 and 2 if Incorrectly Selected

It is not possible to change the Manageability Mode when options 3 or 4 have been selected. 

If Manageability Mode options 1 or 2 are incorrectly selected after replacing the system board, correct this by performing the following steps:

  1. Restart the computer.

  2. Press and hold <Ctrl> while tapping <P> at the Dell logo screen to enter the Intel Management Engine BIOS Extension (MEBx) screens.

  3. When prompted, enter the password and press <Enter>.

  4. Select Intel (R) ME Configuration and press <Enter>.

  5. At the [ Caution ] screen, press <Y>.

  6. At the Intel (R) ME Configuration screen, press <Down Arrow> to select Intel (R) ME Features Control amd Press the <Enter> key.

  7. Press <Enter> to select Manageability Feature Selection.

  8. Use <Up Arrow> or <Down Arrow> to select either Intel (R) AMT or ASF, which are respectively options 1 and 2 when selecting the Manageability Mode on a replacement system board.



Report Unresolved Customer Service Issues
here

I do not work for Dell. I too am a user.

The forum is primarily user to user, with Dell employees moderating
Contact USA Technical Support






Get Support on Twitter @DellCaresPro

0 Kudos
mpanichello
1 Nickel

RE: Optiplex 7040 Enable AMT

Ejn63 is correct. I know there's no simple, or supported, way of doing this, but I have found guides for extracting, modifying, and reflashing the management engine firmware. I guess I'll have to give that a shot.

Saying it's not possible is technically not true - this is a firmware limitation rather than something physically on the board or chip, so all it should require is a modification of that flag. I'll update with a how to if I can get some time to walk through it and document what works.

0 Kudos
mpanichello
1 Nickel

RE: Optiplex 7040 Enable AMT

Success! I updated three Optiplex 7040's from ME disabled to enabled using the Intel Flash Programming Tool and Flash Image Tool. Actually, a very simple procedure! I'll make a new post with a writeup if anyone's interested and if it doesn't violate the site's policy - obviously, this would be completely unsupported by Dell.

0 Kudos
7 Plutonium

RE: Optiplex 7040 Enable AMT

"Saying it's not possible is technically not true" - this is a firmware limitation rather than something physically on the board or chip"

This is not entirely correct because the AMT firmware and Bit Locker requires the TPM chip which is not on embargoed country's motherboard. The No TLS option applies to the following countries: China, France, Hong Kong, Israel, Korea, Poland, and Russia.The microsoft Certificates and SLP Product key are also not stored in the bios chip. Flashing Utilities for BIOS are not made available to the general public.  TPM chips are actually banned and illegal in china and russia etc.  This is also why there are export restrictions on encryption and TPM and other technologies.

 


Report Unresolved Customer Service Issues
here

I do not work for Dell. I too am a user.

The forum is primarily user to user, with Dell employees moderating
Contact USA Technical Support






Get Support on Twitter @DellCaresPro

mpanichello
1 Nickel

RE: Optiplex 7040 Enable AMT

You're correct regarding the TPM being removed from certain motherboards for export restrictions. The TPM isn't required for AMT - it's optional, and the management engine will still function without it.

0 Kudos
akrell1715
1 Copper

RE: Optiplex 7040 Enable AMT

I would be very interested in the answer.  I have the same problem.  

0 Kudos

RE: Optiplex 7040 Enable AMT

Hello, could you post an instruction.

0 Kudos
bluetoe
1 Copper

RE: Optiplex 7040 Enable AMT

Please do post your solution or a link to it. Thanks!

0 Kudos